Skip to content
Training & awareness

Train your teams

DORA requires regular awareness and training for all staff, as well as specific training for executives. Here's how to structure your programme.

The training obligation under DORA

Article 13 of DORA requires every financial entity to put in place ICT security awareness programmes and digital resilience training for all staff. Article 5 adds a specific requirement for the management body, which must maintain sufficient knowledge and skills to understand and oversee ICT-related risks.

Training by profile

Training needs vary by role. Adapt the content to each profile.

Management body & executives
  • Maintain sufficient knowledge of ICT risks to oversee the risk management framework (Art. 5).
  • Approve and regularly review the digital resilience strategy.
  • Undergo dedicated training proportionate to their responsibilities.
CISOs & security/IT teams
  • Deepen DORA's technical requirements and prepare the organisation for compliance.
  • Master incident management, classification and notification deadlines.
  • Stay up to date on RTS/ITS standards and testing methodologies (TLPT).
All staff
  • Awareness of essential cyber best practices: phishing, password management, equipment use.
  • Recognise and quickly report a suspicious incident.
  • Understand their role in the entity's business continuity.
Procurement & vendor management
  • Embed DORA contractual clauses in contracts with ICT providers (Art. 30).
  • Assess provider criticality during selection.
  • Document subcontracting relationships in the information register.

Building your training plan

4 steps to set up an effective awareness programme.

1
Map out needs
Identify the profiles to train, their exposure to ICT risk, and current skills gaps.
2
Choose the right format
E-learning, hands-on workshops, simulations: adapt the format to the profile and level of each audience.
3
Plan and roll out
Build training into a recurring annual plan, with regular sessions and refresher reminders.
4
Measure and improve
Assess what's been learned (quizzes, phishing simulations) and adjust the programme every year.

Official resources

For the French financial sector, the ACPR and AMF publish guides and communications on implementing DORA; the European authorities (EBA, ESMA, EIOPA, ENISA) publish the related technical standards and guides. Find all the useful links on the Sources page.